In our previous post, The ABC’s of Ishing, we broke down the foundational tactics used by cybercriminals to deceive users and gain unauthorized access. This follow-up report expands on that foundation by exploring three evolving phishing threats that go beyond traditional email lures.
Angler Phishing, Calendar Phishing, and Captcha Phishing each exploit trust in everyday digital tools—social media platforms, calendar invites, and CAPTCHA challenges. According to Bitsight Threat Research, these methods are growing in both sophistication and frequency, placing organizations at increased risk.
1. Angler Phishing (Social Media Phishing)
Executive summary
Angler Phishing involves fraudsters creating fake customer support profiles on platforms like Facebook, Instagram, and Twitter. They closely mimic legitimate accounts, responding to user inquiries—especially from frustrated customers—to steal credentials or deliver malware.
Real‑world example
An attack campaign impersonated a major online payment provider’s X (formerly Twitter) support account. Fraudsters monitored posts tagging the real support handle. When users reached out, these fake accounts replied with branded login links. After clicking, victims were redirected to a convincing login prompt that captured their credentials.
Impact
These attacks lead to account takeovers, data theft, reputational harm, and potential business disruption.
Strategic Recommendations
- Train employees to verify support accounts before sharing information.
- Enable MFA on all social media and business accounts.
- Monitor social platforms for impersonator accounts using specialized tools.
- Maintain a ready incident response plan for account compromises.
Report fake accounts promptly to social media platforms. According to Bitsight Threat Research, increased phishing chatter on social media often precedes broader targeting campaigns.